惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园 - 三生石上(FineUI控件)
D
Docker
GbyAI
GbyAI
宝玉的分享
宝玉的分享
Jina AI
Jina AI
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
Vercel News
Vercel News
博客园_首页
Recent Announcements
Recent Announcements
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Hugging Face - Blog
Hugging Face - Blog
腾讯CDC
S
SegmentFault 最新的问题
Microsoft Security Blog
Microsoft Security Blog
酷 壳 – CoolShell
酷 壳 – CoolShell
美团技术团队
V
V2EX
WordPress大学
WordPress大学
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
V
Visual Studio Blog
IT之家
IT之家
Apple Machine Learning Research
Apple Machine Learning Research
T
Tailwind CSS Blog
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com

WhatIs

Strategic IT outlook: Tech conferences and events calendar | TechTarget 8 AI use cases in manufacturing Enterprises are making an AI native transformation Zero trust in the IT ops stack: Securing hybrid workloads How algorithmic value sets enhance clinical decision-making Top methods for collecting customer feedback Build a data governance team that delivers results How to calculate the total cost of ownership of ERP software Communities call for transparency in AI data center deals Scalable IT infrastructure: Balancing speed with stability How health systems are tackling 'Kill the Clipboard' obstacles Understanding the science behind AI-based hiring assessments Tape's strategic role in modern data protection How to choose an HR software system in 2026: A complete guide The UC stack gets the policy job Top zero-trust use cases in the enterprise 13 top IT infrastructure conferences in 2026 SNMP vs. CMIP: What's the difference? 3 essential network analytics use cases AI Security Risks Force CIOs to Rethink Strategy Red Hat Summit 2026 news and conference guide | TechTarget What is HR technology (human resources tech)? Understand, optimize and track customer journey touchpoints Should IT use Apple Business Manager without MDM? Build and organize an effective machine learning team The storage modernization imperative in a fast-changing IT landscape Procurement automation use cases for CSCOs to consider 3 steps for health system leaders to drive patient safety culture What is DevOps? Meaning, methodology and guide Enterprises Face New Storage Bottlenecks as AI Grows
Biggest healthcare data breaches reported to OCR in 2026,...
Jill Hughes · 2026-06-16 · via WhatIs

Hacking remains the top type of healthcare data breach reported to the HHS Office for Civil Rights six months into 2026, underscoring the volatility of the cyberthreat landscape. More than 19 million individuals have been impacted by healthcare data breaches in 2026 as we approach the year's halfway point.

OCR displays healthcare data breaches impacting more than 500 individuals on its breach portal, giving covered entities and the public a peek into this pervasive issue. On the portal, healthcare data breaches fall into four categories: hacking/IT incidents, unauthorized access/disclosure, loss and theft.

So far this year, just one theft has been reported, along with one loss and 14 unauthorized use/disclosures. As of June 9, 2026, the remaining 173 reports were attributed to hacking/IT incidents.

While some of the following data breaches occurred in 2025, this list reflects breaches reported to OCR in 2026. OCR consistently updates its data breach portal, so exact figures may vary.

The 10 largest breaches reported this year so far show that threat actors are continuing to target organizations of all sizes, focusing on provider organizations and business associates alike.

TriZetto Provider Solutions: 3,433,965 individuals affected

Revenue cycle management company TriZetto Provider Solutions filed this year's largest breach report to date in February 2026. The company, owned by IT company Cognizant, handles more than 2.5 billion healthcare transactions annually..

According to a breach notice provided to the Maine Attorney General's Office, TriZetto first became aware of suspicious activity within its systems on Oct. 2, 2025. Upon discovery, the company launched an investigation and notified law enforcement.

Further investigation revealed that an unauthorized party had been accessing records related to insurance eligibility verification transactions since November 2024. TriZetto found that the affected data potentially included names, addresses, Social Security numbers, health insurer names, dates of birth and other demographic and health insurance information.

TriZetto said in its breach notice that it immediately took protective measures to safeguard its systems.

QualDerm Partners: 3,117,874 individuals affected

QualDerm, a healthcare management company that operates a network of over 150 dermatology and cosmetic surgery practices across 17 states, suffered a breach in December 2025.

On Dec. 24, 2025, QualDerm detected unauthorized activity on certain systems and immediately launched an investigation, which determined that an unauthorized individual had removed information from QualDerm's systems.

The impacted information included patient and doctor names, medical record numbers, email addresses, treatment and diagnosis information and health insurance information.

QualDerm said it was unaware of any attempted or actual misuse of the impacted information.

"As part of our ongoing commitment to the privacy of personal information in our care, we are reviewing our existing policies and procedures regarding information security, as well," the notice stated.

QualDerm reported the breach to OCR in February 2026.

Nacogdoches Memorial Hospital: 2,507,073 individuals affected

Nacogdoches Memorial Hospital, a 226-bed hospital in Nacogdoches, Texas, reported a breach to OCR in March 2026. NMH became aware of a data security incident on Jan. 31, 2026, when a cyberattack enabled an unauthorized party to compromise its computer network.

NMH said it immediately notified law enforcement and activated its incident response plan. The impacted information included names, addresses, phone numbers, Social Security numbers, medical account numbers, health plan beneficiary numbers and photographs.

"NMH takes the security of all information in its systems very seriously and wants to assure its patients that it has taken steps to prevent a similar event from occurring in the future," a notice to patients stated.

"This includes implementation of remediation measures to prevent recurrence, to strengthen NMH's network security, enhancing NMH's cyber preparedness through additional awareness training, and updating NMH's procedures."

Navia Benefit Solutions: 2,151,330 individuals affected

Navia Benefit Solutions, a national benefits provider, filed a breach report with OCR in March 2026 after discovering suspicious activity within its environment on Jan. 23, 2026.

Further investigation revealed that an unauthorized party had accessed and potentially acquired information between Dec. 22, 2025, and Jan. 15, 2026. The breach involved names, Social Security numbers, dates of birth, phone numbers, email addresses and health plan information.

Navia said it has since reviewed the security of its systems, notified impacted individuals and assessed its policies and procedures to reduce the likelihood of a similar event in the future.

NYC Health + Hospitals: 1,800,000 individuals affected

NYC Health + Hospitals, the largest municipal healthcare system in the U.S., discovered a cyberattack on its computer network on Feb. 2, 2026. The health system launched an investigation and determined that an unauthorized actor accessed its systems between Nov. 25, 2025, and Feb. 11, 2026, copying files in the process.

"Although the investigation is ongoing, it appears that the unauthorized actor may have gained access to NYC Health + Hospitals systems due to a security breach at a third-party vendor," the health system said in its March 2026 notice.

The breach involved health insurance information, medical and biometric information, billing and claims data, Social Security numbers and financial account information.

In response to the breach, NYC Health + Hospitals said it deployed additional protective technologies across its network, reset credentials for compromised accounts and updated its remote access management policies.

The health system is now facing scrutiny from lawmakers over the breach. Senate Health, Education, Labor, and Pensions Committee Chair Bill Cassidy (R-La.) sent a letter to NYC Health + Hospitals CEO Mitchell Katz on June 4, 2026, seeking answers about the scope and impact of the cyberattack.

OpenLoop Health: 716,000 individuals affected

OpenLoop Health, a white-label telehealth infrastructure vendor, disclosed a breach that occurred on Jan. 7, 2026. The company offers licensing and credentialing, practice management and provider staffing services to digital health companies.

According to a breach notice provided to the California Attorney General's Office, OpenLoop discovered that an unauthorized party had removed certain information from its systems during a cyberattack.

OpenLoop confirmed that the unauthorized access had been terminated. It also  engaged external cybersecurity specialists and arranged complimentary credit monitoring for impacted individuals. It said it would continue to enhance its security posture.

ApolloMD Business Services: 626,540 individuals affected

ApolloMD Business Services, an Atlanta-based healthcare management services organization that provides clinical staffing, practice management and administrative support, experienced a breach in 2025 that it reported to OCR in February 2026.

ApolloMD first became aware of suspicious activity within its IT systems on May 22, 2025, later determining that an unauthorized actor had accessed and potentially acquired information pertaining to patients treated by ApolloMD's affiliated physicians.

The impacted data included names, diagnoses, dates of service, treatment information, health insurance information and Social Security numbers.

ApolloMD notified 11 physician practices of the breach between July and September 2025.

Erie Family Health Centers: 570,000 individuals affected

Illinois-based Erie Family Health Centers experienced a data breach that potentially exposed patient names, email addresses, Social Security numbers, biometric data, prescription information, taxpayer ID numbers, passport numbers and health insurance information.

Erie discovered the breach on Jan. 27, 2026. It launched an investigation that determined an unauthorized party had gained access to Erie's systems between Dec. 10, 2025, and Jan. 27, 2026.

"Erie takes its obligations with respect to the privacy and security of information seriously. We have taken steps to address the incident and are committed to protecting the information entrusted to us," the notice to patients stated.

Erie provided patients with information on safeguarding their information and signing up for complimentary credit monitoring services.

Minnesota Department of Human Services: 303,965 individuals affected

In January 2026, the Minnesota Department of Human Services disclosed a third-party breach to OCR that involved its MnCHOICES system. MnCHOICES is Minnesota's free assessment and support planning system used by counties, tribal nations and managed care organizations to support planning work for individuals who need long-term services.

The breach stemmed from FEI Systems, the vendor that manages MnCHOICES. FEI Systems specializes in providing health IT solutions to federal, state and local agencies. According to the Minnesota Department of Human Services' breach notice, a "provider-associated user" accessed the demographic records of over 300,000 individuals and additional information for 1,206 of those individuals.

The user no longer has access, and there is no evidence that the information has been misused.

"The DHS Office of Inspector General is aware of this incident and has developed data-driven processes to monitor and evaluate billing information, in an effort identify [sic] whether there was fraudulent or inappropriate use of the accessed data," the notice stated.

"If potential fraud is identified, DHS will fully investigate and when appropriate refer those matters to law enforcement."

This breach was the only one in the top 10 that was caused by unauthorized access/disclosure rather than a hacking/IT incident.

North Texas Behavioral Health Authority: 285,086 individuals affected

The North Texas Behavioral Health Authority, a certified community behavioral health clinic, suffered a data breach after learning that a hacker accessed and copied information from its network.

The impacted data included names, Social Security numbers, addresses, driver's license numbers, medical information and health insurance information.

Jill Hughes has covered health tech news since 2021. Her coverage areas include cybersecurity, HIPAA compliance, interoperability, AI and EHRs.